Nigerian Scam Keylogger Tactics Exposed

Want to become a Nigerian scammer? Then turn to a website named PrivateRecovery -- formerly known as BestRecovery -- which offers scamware-as-a-service tools for just $25 to $33 per month.

That information comes by way of security reporter Brian Krebs, who said that an unnamed gray hat hacker had retrieved and shared with him a list of about 3,000 users of PrivateRecovery. The site offers its customers customized keylogging software disguised as a screensaver. Users try to trick their victims into using the malicious software, which records sensitive financial and personal information from victims' PCs. Criminals then retrieve the stolen information via the PrivateRecovery site.

Unfortunately for users of PrivateRecovery, however, the website itself lacks basic information security safeguards. "The site was so poorly locked down that it also exposed the keylog records that customers kept on the service. Logs were indexed and archived each month, and most customers used the service to keep tabs on multiple computers in several countries," Krebs said. "A closer look at the logs revealed that a huge number of the users appear to be Nigerian 419 scammers using computers with Internet addresses in Nigeria."

Who uses PrivateRecovery? "The first thing I noticed upon viewing the user list was that a majority of this service's customers had signed up with yahoo.com emails, and appeared to have African-sounding usernames or email addresses," Krebs said. The user list included numerous email addresses that had been flagged as being used in scams. "Running a simple online search for some of the user emails ([email protected], for example) turned up complaints related to a variety of lottery, dating, reshipping and confidence scams."

Interestingly, some of the keylogger data being stored on the PrivateRecovery site showed that registered users were themselves victims of the site's keylogging software attacks, which suggests that rival scammers may be targeting each other. One likely explanation is that some users have been infecting with keylogging software PCs in Internet cafes from which 419 scammers are known to operate.

Regardless of their victims' identities, PrivateRecovery users appear to be behind a number of Nigerian letter scams, aka "advance fee fraud" or 419 scams, which refers to a section of the Nigerian penal code criminalizing fraud.

Many such scams follow this broad template: The email sender needs money quickly and in return promises future outsize rewards. For example, one message making the rounds Monday -- which even included a calendar attachment notifying the recipient of an impending meeting about the deal -- promised 10% of a contested $37.5 million inheritance and 30% of any profits if the recipient would help move the money from a bank in Sierra Leone to Ivory Coast. "So please i am asking you to send to me your banking informations (sic) as to enable me send it to the bank for introduction of your person as the one to whom the money has to be transferred to for investment in your country which you have to be in control while i (sic) further my education," promised the sender.

Not coincidentally, Ivory Coast is reported to be one hotbed for Nigerian scam operators. Others include India, the Netherlands, Russia, South Africa and Spain.

Why does this far-fetched-sounding fraud persist? As demonstrated by recent FBI alerts, the simple answer is that scammers continue to score more victims using a cheap and easy attack. But this is hardly a new development. Indeed, modern 419 scams were preceded by a late 19th-century "Spanish Prisoner" scam in which a letter writer sought a small investment to help free a wealthy friend -- whose identity, for safety reasons, couldn't be revealed -- in return for a generous reward upon his friend's release. Even prior to that, a "Letter From Jerusalem" seen as early as the 1830s promised generous rewards in exchange for retrieving "a casket containing 16,000 francs in gold and the diamonds of a late marchioness."

As that suggests, regardless of the technological medium -- and throughout history -- human psychology has remained far too easy to hack.

Micro Keylogger records almost all the activities on the computer. Not like other so-called invisible keyloggers, Micro Keylogger is invisible from Desktop, Start Menu, Task Bar and more. It runs in stealth and won't have any impact on the system performance.

Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.

A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in data corrup...

A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) to issue SQL commands, which may result in loss or corruption of data.

Stored cross-site scripting (XSS) vulnerability in the &quot;Site Name&quot; field found in the &quot;site&quot; tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php f...

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prag...